Top photo ID apps leak user data – over 150,000 thought to have been affected



  • Cybernews found three misconfigured photo ID apps leaking sensitive user data via exposed Firebase instances
  • Breach exposed emails, usernames, profile photos, GPS coordinates, and notification tokens, affecting ~152K users
  • Hackers already accessed the open databases; developers remain unresponsive despite repeated contact attempts

Multiple mobile applications that identified objects in photographs were leaking highly sensitive information on the internet, and hackers managed to pick it up.

All three applications had misconfigured Firebase instances resulting in insufficient authentication and access controls. The data was sitting in an open database, and included people’s email addresses, usernames (often including full names), Firebase Cloud Messaging (FCM) notification tokens, profile photos, and GPS coordinates.


https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img